Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.66% | — | Oauth2 Proxy Project Oauth2 Proxy | 14/4/2026 | 24/7/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-agent is set or… | |
| Analizada | Baja (3.5) | 0.22% | — | Oauth2 Proxy Project Oauth2 Proxy | 14/4/2026 | 24/7/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout flow, a user may be shown the sign-in page… | |
| Analizada | Alta (8.8) | 0.64% | — | Jupyter Oauthenticator | 3/4/2026 | 24/7/2026 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the… | |
| Analizada | Media (4.2) | 0.21% | — | Bojanz Openid Connect / Oauth Client | 26/3/2026 | 17/6/2026 | Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Analizada | Media (6.5) | 0.42% | — | Bojanz Openid Connect / Oauth Client | 26/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Analizada | Media (4.3) | 0.27% | — | Bojanz Openid Connect / Oauth Client | 26/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Analizada | Alta (8.8) | 0.31% | — | Goauthentik Authentik | 12/2/2026 | 17/6/2026 | authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Advanced Protocol… | |
| Analizada | Alta (7.5) | 0.78% | — | Goauthentik Authentik | 12/2/2026 | 17/6/2026 | authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cookie was used, none of… | |
| Analizada | Alta (7.2) | 0.83% | — | Goauthentik Authentik | 12/2/2026 | 17/6/2026 | authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server container through the test… | |
| Aplazada | Media (5.3) | 0.38% | — | Miniorange Oauth Single Sign ONAI | 6/2/2026 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and authentication verification on the OAuth redirect functionality accessible via the 'oauthredirect' option parameter. This… | |
| Analizada | Media (5.3) | 0.25% | — | Goauthentik Authentik | 19/11/2025 | 17/6/2026 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired or not, thus relying on background tasks to clean up expired ones. In a normal scenario this can take up to 5 minutes because the… | |
| Analizada | Media (4.8) | 0.22% | — | Goauthentik Authentik | 19/11/2025 | 17/6/2026 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this account was possible even when the account… | |
| Aplazada | Media (6.1) | 0.32% | — | Wp-oauthAI | 11/11/2025 | 17/6/2026 | The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (8.5) | 0.62% | — | Oauth2 ProxyAI | 10/11/2025 | 17/6/2026 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions prior to 7.13.0, all deployments of OAuth2 Proxy in front of applications that normalize underscores to dashes in HTTP headers… | |
| Analizada | Alta (7.5) | 0.36% | — | Simple Oauth Project Simple Oauth | 30/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7. | |
| Aplazada | Crítica (9.8) | 0.60% | 💥 PoC | Oauth Single Sign ON SSOAI | 4/10/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token`… | |
| Aplazada | Media (4.3) | 0.17% | — | Miniorange Oauth Single Sign ONAI | 26/9/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64 encoded app name) without any randomness in the OAuth flow. This makes it possible for unauthenticated… | |
| Analizada | Crítica (9.1) | 1.2% | — | Oauth2 Proxy Project Oauth2 Proxy | 30/7/2025 | 17/6/2026 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using the skip_auth_routes configuration option with regex patterns.… | |
| Analizada | Alta (7.1) | 0.53% | — | Goauthentik Authentik | 23/7/2025 | 17/6/2026 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered through OAuth/SAML or linked their accounts to OAuth/SAML providers… | |
| Analizada | Media (5.5) | 0.52% | — | Goauthentik Authentik | 27/6/2025 | 17/6/2026 | authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the connection, however this check is… | |
| Analizada | Crítica (9.8) | 0.64% | — | Jenkins Wso2 Oauth | 14/5/2025 | 17/6/2026 | In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist. | |
| Analizada | Media (5.3) | 0.57% | — | Cloudflare Workers-oauth-provider | 1/5/2025 | 17/6/2026 | PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/27… | |
| Analizada | Media (6) | 0.32% | — | Cloudflare Workers-oauth-provider | 1/5/2025 | 17/6/2026 | The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/26… | |
| Aplazada | Media (5.4) | 0.27% | — | Wikimedia Mediawiki Oauth ExtensionAI | 11/4/2025 | 17/6/2026 | Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawiki - OAuth Extension: from 1.39 through 1.43. | |
| Analizada | Crítica (9.8) | 0.43% | — | Oauth2 Server Project Oauth2 Server | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0. |